The package is licensed and has no install-time scripts, keeping basic adoption risks low. Its only release was about 2 years and 8 months ago, with no recent commits and no tests or security policy, while the repository does not clearly identify the package.
45%
Total Score
0
100
63
75
Only one release exists, published about 2 years and 8 months ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The repository has had no commits and no active maintainers in the last 3 months. Combined with the one-release history, this indicates a likely abandoned project.
The repository name does not match the package name and its README does not mention the package. This creates uncertainty that the linked source repository actually belongs to the published package.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these figures provide no additional sign of community validation.
Composer is used for the build, which is appropriate, but no security scanning tools are configured. This is a modest hygiene gap rather than a standalone adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.6 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.